This page is maintained by West Valley Courier Solutions LLC to answer common security and privacy questions about the WVC command console. It describes our current practices and the platform capabilities we rely on. It is editable project content and is not a certification or independent verification.
Shared Responsibility
WVC operates the application, configures access controls, and defines data handling practices. Our hosting and backend platform provides the underlying infrastructure, managed authentication, database, and serverless compute. Customers and operators are responsible for safeguarding their credentials and using the console in accordance with their own policies and applicable law.
Access & Authentication
Console access requires an authenticated account. Operator sessions are scoped to authenticated routes and protected by managed authentication on our backend platform. Sessions can be terminated at any time using the EJECT control in the console header.
Platform & Hosting
The application is hosted on a managed serverless platform with TLS in transit. The database enforces row-level access policies so that operator data is scoped to the authenticated user or role that owns it. These are platform capabilities we have enabled — not third-party certifications.
Data Collection & Use
We collect only the operational data needed to run courier dispatch, chain of custody, incident response, and ledger workflows. Details on categories of data, purposes, and your rights are described in our Privacy Policy. Protected health information handling is covered in our HIPAA Notice.
Subprocessors & Integrations
WVC uses a managed backend platform for authentication, database, and serverless functions, and a managed hosting provider for application delivery. Additional subprocessors may be engaged to support email, analytics, or operational tooling. Contact us at operations@wvc.solutions for the current list applicable to your engagement.
Retention & Deletion
Operational records are retained for as long as needed to deliver the service and to meet legal, tax, and regulatory obligations under Arizona law. Customers may request deletion of account data by contacting operations@wvc.solutions; some records may be retained where required by law or to resolve disputes.
Privacy Requests
To exercise data access, correction, or deletion rights, email operations@wvc.solutions from the address associated with your account. We will respond within the timeframes required by applicable law.
Incident & Security Contact
Report a suspected security issue or incident to operations@wvc.solutions or call (602) 796-9261. Please include reproduction steps and any relevant timestamps. Do not include sensitive personal data in the initial report.
Vulnerability Reporting
We welcome responsible disclosure. Send findings to operations@wvc.solutions. Please give us a reasonable window to investigate and remediate before public disclosure, and avoid testing that could degrade service or access data that is not yours.
Compliance
WVC aligns its operations with applicable Arizona and U.S. federal requirements relevant to courier and healthcare logistics work, including HIPAA obligations when handling protected health information under a Business Associate Agreement. This page does not assert third-party certifications; contact operations@wvc.solutions for documentation relevant to a specific engagement.
